Merge PDFs without uploading them: what runs in the browser and what gets lost

Updated 5 min read

A contract, a tax return and a scanned ID are exactly the files people merge into one PDF, and many free merge sites do the work on a server. You upload the files, wait, and download a result, with whatever retention policy the site has in between. Merging does not need that: a PDF is a structured file, and a program running in your browser tab can copy pages from one into another.

How to tell whether a site uploads your files

Do not rely on the wording of the page. The browser can show you. Open DevTools (F12), switch to the Network tab, clear the list, then add a file. A tool that works locally shows no request carrying your file. A tool that uploads shows a POST or a PUT with a payload about the size of your PDF.

Two details can mislead you. First, a local tool still makes requests, for example to fetch its own code. The PDF merger on this site loads its PDF library, about 200 kB compressed, the first time you add a file, and the page shows “PDF engine loaded.” when that finishes. That request carries no document. Second, you can go further: once that message appears, turn off your network connection. A tool that keeps working while offline cannot be sending your pages anywhere.

What the merger does with the files

The files are read in the tab and parsed with pdf-lib, a JavaScript PDF library. Merging copies page objects from each source document into a new document, in the order you set, and then saves it. Before offering a download, the tool re-opens the result and checks the page count against what it expected; if the two disagree it refuses to offer the file.

The order is simple: files in the order of the list, then each file’s pages in their own order. You can reorder files with the Up and Down buttons or by dragging, and reorder pages within a file. Pages cannot move between files; to interleave two documents, you would merge, then handle the result in a second step.

Each page appears as a numbered chip. Clicking one excludes that page from the merge, and its number is crossed out. Long files show the first 48 chips, with a button to reveal 48 more at a time.

Picking pages by number

The range box accepts entries such as 1-4, 7. The numbers refer to the merged order, not to a page’s original number, and excluded pages do not count. Suppose two files of 10 pages each and you exclude page 3 of the first: the merged document has 19 pages, and “11” now means the second page of the second file. Reversed ranges such as 5-2 are read as 2-5. Entries that are out of range or not numbers are reported rather than silently clamped, so a typo stays visible.

The same selection drives the Extract button, which outputs only the selected pages. It is the quick way to pull pages 4 to 6 out of a long report.

What does not survive

pdf-lib copies page objects; it does not draw them. The consequences are honest limits:

ItemWhat happens
ThumbnailsNone. Pages are numbered chips, because nothing here renders content
Password-protected PDFsRejected with an error on that file’s row
Document title, author, subject, keywordsNot carried over
Bookmarks and page labels (roman numerals)Not carried over
Form fields, annotations, embedded JavaScriptMay not survive a page copy
Digital signaturesMay not survive; treat the output as a reading copy, not a certified one

Metadata and bookmarks are the ones people notice late: a 200-page report with a clickable outline comes out the other side as 200 plain pages. The merged file also carries a new creation date and names pdf-lib as its producer. If the outline matters, rebuild it in a PDF editor after merging.

A signed PDF is a special case. The signature covers the exact bytes of the original, so copying its pages into a new file cannot keep it valid. If you need a signed document inside a bundle, attach the original file alongside the merged one.

Encrypted files

A PDF can be protected by a password in different ways, and the tool takes the simple route: any encrypted file is rejected, because pdf-lib refuses to open it. The row shows that message and the other files continue. Remove the password with whatever software set it, or open the file and print it to a new PDF if the document’s permissions allow it, then add the new copy.

Big jobs and memory

Everything is held in memory in one tab. pdf-lib keeps each parsed document and a copy of every page it copies. The tool accepts any size, but above 60 MB in total or more than 2000 pages it stops and asks you to press the button a second time. Pressing again is a decision to risk it: a tab that runs out of memory can crash, and you lose the work in it. If you reach that point, merge in stages, for example 10 files into 1, then the 4 results into one.

Smaller guards at the start of the pipeline: only files typed application/pdf or named .pdf are read, an empty file is refused, and a file with no readable pages is reported on its own row. A file that fails does not block the others.

What the check can and cannot prove

The tool reports the page count of the result and the size before and after. That tells you the file opened and has the pages you expected. It cannot tell you that page 7 shows what you think, since no page is rendered in the tool. After any merge that matters, open the output in a PDF viewer and scroll through it once, especially where scanned pages with different orientations or sizes meet.

The finished PDF is a Blob built in your tab and downloaded from there. “Download again” reuses it. Clear all releases the files and the result from memory.

Open the tool: PDF Merger & Page Extractor

Back to guides

More guides